Red Hat Enterprise Linux (RHEL)
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Red Hat Enterprise Linux (RHEL).
Recent Red Hat Enterprise Linux (RHEL) Security Advisories
| Advisory | Title | Published |
|---|---|---|
| RHSA-2026:46956 | (RHSA-2026:46956) Red Hat Enterprise Linux AI 3.3.5 | July 27, 2026 |
| RHSA-2026:43855 | (RHSA-2026:43855) Red Hat Enterprise Linux AI 3.3.5 | July 22, 2026 |
| RHSA-2026:43853 | (RHSA-2026:43853) Red Hat Enterprise Linux AI 3.3.5 | July 22, 2026 |
| RHSA-2026:43854 | (RHSA-2026:43854) Red Hat Enterprise Linux AI 3.3.5 | July 22, 2026 |
| RHSA-2026:43851 | (RHSA-2026:43851) Red Hat Enterprise Linux AI 3.3.5 | July 22, 2026 |
| RHSA-2026:43670 | (RHSA-2026:43670) Red Hat Enterprise Linux AI 3.3.5 | July 22, 2026 |
| RHSA-2026:43651 | (RHSA-2026:43651) Red Hat Enterprise Linux AI 3.3.5 | July 22, 2026 |
| RHSA-2026:33531 | (RHSA-2026:33531) Red Hat Enterprise Linux AI 3.4.1 enhancement update | June 30, 2026 |
| RHSA-2026:33524 | (RHSA-2026:33524) Red Hat Enterprise Linux AI 3.4.1 enhancement update | June 30, 2026 |
| RHSA-2026:17611 | (RHSA-2026:17611) Red Hat Enterprise Linux AI 3.3.3 | May 14, 2026 |
By the Year
In 2026 there have been 1151 vulnerabilities in Red Hat Enterprise Linux (RHEL) with an average score of 7.1 out of ten. Last year, in 2025 Enterprise Linux (RHEL) had 213 security vulnerabilities published. That is, 938 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.60.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1151 | 7.12 |
| 2025 | 213 | 6.52 |
| 2024 | 172 | 6.36 |
| 2023 | 212 | 6.38 |
| 2022 | 176 | 6.72 |
| 2021 | 148 | 6.50 |
| 2020 | 104 | 6.35 |
| 2019 | 293 | 6.21 |
| 2018 | 113 | 7.02 |
It may take a day or so for new Enterprise Linux (RHEL) vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Red Hat Enterprise Linux (RHEL) Security Vulnerabilities
Red Hat multipathd IPC DoS via blocked listener thread
CVE-2026-89329
6.2 - Medium
- September 11, 2026
A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` listener thread to block, leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. This issue does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity.
Use of Blocking Code in Single-threaded, Non-blocking Context
libtiff tiff2pdf Heap-BUF Overflow via Truncated StripByteCounts
CVE-2026-18495
6.1 - Medium
- September 11, 2026
A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.
Heap-based Buffer Overflow
Privilege Escalation via Symlink Chown in libvirt qemuTPMEmulatorPrepareHost
CVE-2026-77159
5.5 - Medium
- September 11, 2026
A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm account can replace the logfile with a symlink, causing libvirtd (running as root) to transfer ownership of an arbitrary file to the swtpm user.
Symlink following
GStreamer gst-plugins-good isomp4 Integer Overflow in Closed-Caption Parser
CVE-2026-88914
4.4 - Medium
- September 11, 2026
A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds check in the caption parser. This leads to an out-of-bounds heap read of up to 244 bytes, which is then included in the downstream caption output. An attacker could exploit this by tricking a user into opening a malicious media file, potentially resulting in disclosure of adjacent heap memory or application crash.
Integer Overflow or Wraparound
Local Privilege Escalation via TOCTOU in gvfsd-admin (Red Hat)
CVE-2026-88924
7 - High
- September 10, 2026
A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an arbitrary root-owned file (such as /etc/pam.d/su). The daemon subsequently follows the symlink and changes the ownership of the targeted root-owned file to the attacker's user ID. This allows an authenticated local attacker to modify critical system files, leading to a full local privilege escalation to root.
TOCTTOU
Evolution JS Execution via Spoofed vCard Control in HTML Email
CVE-2026-88859
6.3 - Medium
- September 10, 2026
A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript handler incorrectly assigns an attacker-controlled JavaScript URL to an iframe's source. This action leads to arbitrary JavaScript execution within the mail-viewing context, effectively bypassing the security measures designed to prevent script execution in email content.
Improper Neutralization of Encoded URI Schemes in a Web Page
PCS: Local File Disclosure via pcs host auth --token
CVE-2026-84828
6.5 - Medium
- September 10, 2026
A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided the files are shorter than 256 bytes. The file contents are read with root privileges by the pcsd daemon and can be exfiltrated by the attacker through subsequent cluster node communication. This allows disclosure of sensitive data such as API keys, tokens, or configuration secrets that would otherwise be inaccessible to the attacker.
Incorrect Permission Assignment for Critical Resource
FreeIPA Web UI DOM XSS in Password Reset
CVE-2026-18147
8.1 - High
- September 09, 2026
A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and complete a password reset, the attacker could inject and execute arbitrary JavaScript code. This allows the attacker to perform actions within the victim's authenticated session, potentially leading to full administrative control if an IdM administrator is targeted.
XSS
CUPS Username ACL Bypass via Case-Insensitive Comparisons
CVE-2026-87876
3 - Low
- September 09, 2026
Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.
Improper Handling of Case Sensitivity
CUPS UTF32ToUTF8 Heap OOB Read via SNMP
CVE-2026-87875
4.3 - Medium
- September 09, 2026
The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.
Out-of-bounds Read
SSSD IdP OIDC Subject Prefix Auth Flaw
CVE-2026-87853
7.5 - High
- September 09, 2026
A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of an exact match. An attacker whose IdP identifier is a strict prefix of a target user's identifier can authenticate as the target user.
Partial String Comparison
Bubblewrap <0.12.0: Symlink Escape via /oldroot During Sandbox Setup
CVE-2026-87766
8.8 - High
- September 09, 2026
A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This happens before the sandboxed process starts. This issue is GHSA-pxhw-h44j-8pfx. It is fixed in bubblewrap 0.12.0.
insecure temporary file
DPDK lib/vhost OOB read in virtio-net controlqueue crash
CVE-2026-86564
3.3 - Low
- September 08, 2026
A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.
Out-of-bounds Read
gdk-pixbuf ICNS RLE Heap OOB Read/Info Disclosure via Crafted .icns
CVE-2026-18090
6.1 - Medium
- September 08, 2026
A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon data, fails to validate the source buffer's boundaries during decompression. This can lead to a denial of service, where the application crashes, or to information disclosure, potentially revealing sensitive data from adjacent memory.
Out-of-bounds Read
libxml2 Python SAX Binding Double-Free DoS CVE-2026-74860
CVE-2026-74860
8.5 - High
- September 08, 2026
A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.
Release of Invalid Pointer or Reference
GnomeTweaks ZIP Extraction Path Traversal in Theme Installer
CVE-2026-74859
6.8 - Medium
- September 08, 2026
The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. As a result, a crafted theme archive can write files outside ~/.themes by using ../ path traversal, absolute paths, or symlink entries.
Directory traversal
Dogtag PKI ExternalProcessConstraint RCE via Unvalidated Profile Import
CVE-2026-76561
7.2 - High
- September 08, 2026
A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Administrator privileges can exploit Dogtag's ExternalProcessConstraint mechanism to execute arbitrary commands with attacker-controlled environment variables, achieving code execution as the pkiuser account.
Shell injection
Race Condition in GLib2 g_file_replace() Enables File Redirect
CVE-2026-86469
5.3 - Medium
- September 07, 2026
A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.
insecure temporary file
Privilege Escalation via LDAP Shell Injection in 389 Console
CVE-2026-19843
8.4 - High
- September 07, 2026
A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN containing shell metacharacters. When a Cockpit administrator subsequently views the entry in the 389 Console, the embedded shell command executes with root privileges on the directory server host.
Shell injection
389 DS Stale Identity Exploit via SASL PLAIN Auth
CVE-2026-18922
9.8 - Critical
- September 07, 2026
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.
authentification
389 Directory Server NULL Pointer Crash via USE_ONE_BACKEND Control
CVE-2026-18453
7.5 - High
- September 07, 2026
A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resulting in denial of service.
NULL Pointer Dereference
389-DS SASL I/O Heap Overflow via Small-Length Underflow
CVE-2026-18355
7.5 - High
- September 07, 2026
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted_buffer_count below the already-consumed encrypted_buffer_offset, causing an unsigned subtraction underflow in sasl_io_read_packet(). PR_Recv is then requested to read approximately 4 GiB into a 1024-byte heap buffer, resulting in a heap buffer overflow with attacker-controlled content. After a successful SASL bind with integrity protection (SSF > 0), a remote authenticated attacker can cause a denial of service or potentially achieve remote code execution. This flaw is distinct from CVE-2026-11774, whose fix only guards against upper-bound overflow.
Integer underflow
Unauth LDAP Client Bypasses SELFDN ACI in 389 DS
CVE-2026-76560
7.5 - High
- September 07, 2026
A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a directory entry, that a SELFDN-based ACI intended to restrict to a specific authenticated user.
AuthZ
FreeIPA idp-add Eval() RCE & DoS via Unvalidated --organization
CVE-2026-79678
8.1 - High
- September 07, 2026
A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated IPA principal, regardless of privilege level, to enumerate and read the environment variables of the affected server process and to cause denial of service via memory exhaustion.
Eval Injection
FreeIPA LDAP ACI Flaw Grants Unauth Admin Privileges
CVE-2026-76578
9.8 - Critical
- September 07, 2026
A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory server's ACI evaluation (tracked separately), to create an arbitrary attacker-controlled Kerberos principal and have it added to the administrators group. This allows a remote, unauthenticated attacker to obtain genuine FreeIPA administrator-group membership and perform administrative operations against the directory and, on SID-enabled deployments, other IdM services.
Missing Authentication for Critical Function
Flatpak SystemHelper TOCTOU Race in Deploy() File Manipulation
CVE-2026-76925
5.8 - Medium
- September 04, 2026
A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop.Flatpak.SystemHelper` component. This vulnerability occurs because a privileged `chmod` operation executes before the OSTree repository validation within the `Deploy()` function. An attacker can exploit this timing window to redirect symlinks to arbitrary files, potentially leading to unauthorized file manipulation or information disclosure.
TOCTTOU
libtpms DoS via Oversized skip-block in TPM state restore
CVE-2026-85769
6.5 - Medium
- September 04, 2026
A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for example during a virtual machine's power-on or state/migration restore), a malformed state blob can supply an oversized skip-block length that is not validated against the remaining size of the input buffer. This can drive an internal size counter negative, which bypasses a subsequent bounds check due to an unsafe signed-to-unsigned conversion, causing the parser to read memory outside the bounds of the heap buffer holding the state data. Successful exploitation can crash the process hosting libtpms (such as swtpm), resulting in a denial of service of the emulated TPM device and the virtual machine that depends on it. No data corruption or information disclosure was confirmed.
Out-of-bounds Read
libsoup HTTP/2 Flow Control Window Size Buffer Overflow
CVE-2026-85534
5.9 - Medium
- September 04, 2026
A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control window later allows. A malicious HTTP/2 server can shrink SETTINGS_INITIAL_WINDOW_SIZE while that buffered read is still in progress. The client then copies the full buffer into a smaller DATA callback without a runtime bounds check, which can abort the process or fail the HTTP/2 session.
assertion failure
Corosync Int Overflow in Membership Commit Token Msg (CVE-2026-81666)
CVE-2026-81666
6.5 - Medium
- September 04, 2026
An integer overflow was found in Corosync's handling of membership commit token messages. The length-validation check for these messages can be bypassed on 32-bit systems due to an integer overflow in the calculation of the expected message length, allowing a crafted network packet to trigger an out-of-bounds memory access that crashes the Corosync daemon. This results in a denial of service for the affected cluster node. The overflow does not occur on 64-bit systems, where the length calculation is correctly performed in 64-bit arithmetic.
Integer Overflow or Wraparound
Corosync TotemPG Heap Overflow (CVE-2026-81665)
CVE-2026-81665
7.5 - High
- September 04, 2026
A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send crafted multicast protocol messages to the cluster could cause a heap buffer overflow with attacker-controlled data. This can crash the Corosync daemon, causing a denial of service to the entire cluster, and may potentially allow further exploitation given sufficient heap-corruption control.
Heap-based Buffer Overflow
libsoup HTTP/2 Heap UAF Arb. Code Exec
CVE-2026-85197
7.6 - High
- September 04, 2026
A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using HTTP/2, and the server sends a GOAWAY frame while the file body is being read asynchronously. This can lead to memory corruption, potentially resulting in information disclosure or arbitrary code execution.
Dangling pointer
jwcrypto General JWS Verification Bypass via Key ID Misidentification
CVE-2026-84185
5.9 - Medium
- September 03, 2026
A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the library verifies a General JSON Serialization JWS using a set of keys. Due to a coding error, the library fails to correctly identify the specific key ID (kid) and may instead accept a signature made by any valid key in the set. This can allow an attacker with a valid key to bypass authorization checks in applications that rely on the key ID to identify specific tenants or users.
Improper Verification of Cryptographic Signature
Stack Overflow in gfs2-utils Metadata Walk via untrusted inode height
CVE-2026-71224
4.7 - Medium
- September 03, 2026
A stack overflow vulnerability was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca() with an untrusted inode height value from on-disk metadata without bounds validation, causing stack exhaustion and a denial of service when processing crafted GFS2 filesystem images.
Allocation of Resources Without Limits or Throttling
Red Hat GFS2-Utils Heap OOB Read in ea_num_ptrs
CVE-2026-71222
5.3 - Medium
- September 03, 2026
A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute metadata is consumed without bounds validation, causing a heap buffer over-read that may disclose sensitive memory contents or cause a crash when processing crafted GFS2 filesystem images.
Out-of-bounds Read
Stack OOB Write in RedHat gfs2-utils savemeta Arbitrary Code Execution
CVE-2026-71221
7 - High
- September 03, 2026
A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images.
Memory Corruption
Stack OOB Write in gfs2-utils (Red Hat)
CVE-2026-71220
7 - High
- September 03, 2026
A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field from on-disk inode metadata is used as an array index without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images.
Memory Corruption
Stack Overflow in gfs2-utils via di_depth overflow DoS
CVE-2026-71219
4.7 - Medium
- September 03, 2026
A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-disk di_depth field without bounds validation. A crafted GFS2 filesystem image with a large di_depth value causes stack exhaustion and a denial of service when processed by fsck.gfs2, gfs2_edit, or savemeta.
Allocation of Resources Without Limits or Throttling
GStreamer RTSP Digest Auth NULL Deref DoS
CVE-2026-85150
7.5 - High
- September 03, 2026
A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity.
NULL Pointer Dereference
RedHat RPM rpmuncompress Command Injection via Unescaped Filename
CVE-2026-84838
7.8 - High
- September 02, 2026
A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings. Successful exploitation requires user interaction, where a user or automated workflow invokes rpmuncompress on the malicious file, leading to high impact on the confidentiality, integrity, and availability of data accessible to the invoking user.
Shell injection
Command Injection in rpmbuild via Path Manipulation
CVE-2026-84837
7.8 - High
- September 02, 2026
A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of the build user, which could lead to information disclosure or disruption of the build environment.
Shell injection
Linux Kernel 6.15+ X-mount.subdir Symlink Traversal Local PrivEsc
CVE-2026-78409
7 - High
- September 02, 2026
The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.
insecure temporary file
util-linux Local Privilege Escalation via Redirected Restricted Bind Mount
CVE-2026-78410
7.8 - High
- September 02, 2026
A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.
TOCTTOU
CVE-2026-78408: nsenter --join-cgroup root-FD leak allows cgroup migration
CVE-2026-78408
7.9 - High
- September 02, 2026
The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.
Missing Release of File Descriptor or Handle after Effective Lifetime
Red Hat Password_Reset Unvalidated Redirect
CVE-2026-53683
4.3 - Medium
- September 02, 2026
reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect users to an arbitrary external site after completion of the password-reset workflow.
Open Redirect
GVFS MTP Backend DoS via unchecked memcpy
CVE-2026-84270
4.3 - Medium
- September 01, 2026
A flaw was found in the MTP backend in gvfs. When reading a file from a mounted MTP device, do_read() in gvfsbackendmtp.c trusts the data length returned by the device without limiting it to the original size requested by the client. If a malicious MTP device responds with more bytes than requested, this unrestricted length is passed directly to memcpy(). This causes the operation to read memory outside the intended boundaries. This allows an attacker who plugs in a malicious MTP device to cause a segmentation fault when a file is read and crash the gvfsd-mtp process, resulting in a denial of service.
Out-of-bounds Read
gvfs AFP backend heap overflow causing DoS
CVE-2026-84269
6.5 - Medium
- September 01, 2026
A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the pre-sized reply buffer, causing the operation to access past the intended boundaries. This issue allows a malicious server to overflow a heap buffer and crash the gvfsd-afp process, resulting in a denial of service.
Heap-based Buffer Overflow
GVFS SFTP Backend Buffer Uninitialized Leak Enables ASLR Bypass
CVE-2026-84267
4.3 - Medium
- September 01, 2026
A flaw was found in the SFTP backend in gvfs. When mounting a share, a malicious SFTP server can cause read_string() to allocate a buffer with a certain length but the function does not verify that the buffer is completely filled, leaving the remainder of the buffer containing uninitialized heap contents. If the server sends a short FXP_HANDLE reply, these uninitialized bytes are taken as the file handle. The client will then echo these uninitialized bytes back to the server on all subsequent requests using that handle. With a length of 128 bytes, this issue allows the malicious server to deterministically read uninitialized heap memory from the gvfsd-sftp process, leaking its heap base and the load address of the libgio library, resulting in a deterministic defeat of Address Space Layout Randomization (ASLR).
Use of Uninitialized Resource
GVFS SFTP Backend Buffer Overflow in read_reply()
CVE-2026-84268
8.8 - High
- September 01, 2026
A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrupt adjacent heap memory in the gvfsd-sftp process, resulting in a denial of service as the process aborts upon detecting the heap corruption or potentially allowing arbitrary code execution.
Heap-based Buffer Overflow
Local Command Execution via Macro Expansion in rpm's rpmuncompress
CVE-2026-84233
7 - High
- September 01, 2026
A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability.
Shell injection
Red Hat Unauth Query of Security Domain Hosts via /ca/rest API
CVE-2026-53682
5.3 - Medium
- September 01, 2026
An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal, client certificate, or session.
Information Disclosure
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Red Hat Enterprise Linux (RHEL) or by Red Hat? Click the Watch button to subscribe.